CVE Vulnerabilities

CVE-2016-11029

Insufficiently Protected Credentials

Published: Apr 07, 2020 | Modified: Apr 07, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Attackers can read the password of the Mobile Hotspot in the log because of an unprotected intent. The Samsung ID is SVE-2016-7301 (December 2016).

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Android Google 5.0 (including) 5.0 (including)
Android Google 5.1 (including) 5.1 (including)
Android Google 6.0 (including) 6.0 (including)
Android Google 7.0 (including) 7.0 (including)

Potential Mitigations

References